Authentication using non-fungible token as proof of account ownership
A processor-implemented method may be performed by a server. A method may include: receiving an authentication request from a device, the authentication request including a unique identifier; authenticating the authentication request by: retrieving a non-fungible token (NFT) identifier and public key associated with the unique identifier; identifying, from a blockchain, a blockchain address that is an owner of an NFT represented by the NFT identifier; verifying that the blockchain address that is the owner of the NFT is associated with the public key that is associated with the unique identifier; and verifying that a private key stored in a secure area of the device is associated with the public key that is associated with the unique identifier; and after authenticating the authentication request, enabling an operation not available prior to authenticating the authentication request. The unique identifier may be obtained using image recognition or optical character recognition.
1 . A computing system comprising:
a communications module;
a processor coupled with the communications module; and
a memory coupled to the processor and storing processor-executable instructions which, when executed by the processor, configure the computing system to:
receive an authentication request from a device, the authentication request including a unique identifier;
authenticate the authentication request by:
retrieving a non-fungible token (NFT) identifier and public key associated with the unique identifier;
identifying, from a blockchain, a blockchain address that is an owner of an NFT represented by the NFT identifier;
verifying that the blockchain address that is the owner of the NFT is associated with the public key that is associated with the unique identifier; and
verifying that a private key stored in a secure area of the device is associated with the public key that is associated with the unique identifier; and
after authenticating the authentication request, enable an operation not available prior to authenticating the authentication request.
2 . The computing system of claim 1 , wherein the unique identifier is a primary account number for a payment credential and wherein enabling the operation includes enabling completion of a transaction at a point-of-sale terminal using the payment credential.
3 . The computing system of claim 2 , wherein enabling the completion of the transaction includes setting an authentication flag associated with the NFT identifier to indicate that the authentication request has been authenticated.
4 . The computing system of claim 2 , wherein the processor is further configured to cause the computing system to send the NFT identifier to the point-of-sale terminal, and wherein the point-of-sale terminal is configured to generate a personal identification number (PIN) block for a transaction message based on the NFT identifier.
5 . The computing system of claim 4 , wherein the instructions further cause the computing system to determine that an authentication flag associated with an NFT identifier represented by a PIN block for a received transaction message is set to indicate that an authentication request has been authenticated.
6 . The computing system of claim 1 , wherein the processor is further configured to cause the computing system to link a unique identifier with an NFT by:
receiving, from a device, the public key associated with the unique identifier, the public key forming a key pair with the private key stored in the secure area of the device;
assigning ownership of an NFT to a blockchain public address derived from the public key; and
storing an NFT identifier associated with the NFT in association with the unique identifier.
7 . The computing system of claim 6 , wherein the unique identifier is associated with a payment card that is issued digitally and wherein the processor is configured to cause the computing system to link the unique identifier with the NFT after the device has received a digital representation of the payment card.
8 . The computing system of claim 6 , wherein the key pair is generated within the secure area of the device.
9 . The computing system of claim 1 , wherein the authentication request is received from the device in response to the device scanning a machine-readable code displayed on a point-of-sale terminal.
10 . The computing system of claim 1 , wherein the unique identifier is obtained via image recognition of an image captured of a physical token, and wherein the image recognition includes optical character recognition.
11 . A method comprising:
receiving an authentication request from a device, the authentication request including a unique identifier;
authenticating the authentication request by:
retrieving a non-fungible token (NFT) identifier and public key associated with the unique identifier;
identifying, from a blockchain, a blockchain address that is an owner of an NFT represented by the NFT identifier;
verifying that the blockchain address that is the owner of the NFT is associated with the public key that is associated with the unique identifier; and
verifying that a private key stored in a secure area of the device is associated with the public key that is associated with the unique identifier; and
after authenticating the authentication request, enabling an operation not available prior to authenticating the authentication request.
12 . The method of claim 11 , wherein the unique identifier is a primary account number for a payment credential and wherein enabling the operation includes enabling completion of a transaction at a point-of-sale terminal using the payment credential.
13 . The method of claim 12 , wherein enabling the completion of the transaction includes setting an authentication flag associated with the NFT identifier to indicate that the authentication request has been authenticated.
14 . The method of claim 12 , further comprising sending the NFT identifier to the point-of-sale terminal, and wherein the point-of-sale terminal is configured to generate a personal identification number (PIN) block for a transaction message based on the NFT identifier.
15 . The method of claim 14 , further comprising determining that an authentication flag associated with an NFT identifier represented by a PIN block for a received transaction message is set to indicate that an authentication request has been authenticated.
16 . The method of claim 11 , further comprising linking a unique identifier with an NFT by:
receiving, from a device, the public key associated with the unique identifier, the public key forming a key pair with the private key stored in the secure area of the device;
assigning ownership of an NFT to a blockchain public address derived from the public key; and
storing an NFT identifier associated with the NFT in association with the unique identifier.
17 . The method of claim 16 , wherein the unique identifier is associated with a payment card that is issued digitally and wherein the linking of the unique identifier with the NFT is performed after the device has received a digital representation of the payment card.
18 . The method of claim 16 , wherein the key pair is generated within the secure area of the device.
19 . The method of claim 11 , wherein the authentication request is received from the device in response to the device scanning a machine-readable code displayed on a point-of-sale terminal.
20 . A non-transitory computer readable storage medium comprising computer-executable instructions which, when executed, cause a computing system to:
receive an authentication request from a device, the authentication request including a unique identifier;
authenticate the authentication request by:
retrieving a non-fungible token (NFT) identifier and public key associated with the unique identifier;
identifying, from a blockchain, a blockchain address that is an owner of an NFT represented by the NFT identifier;
verifying that the blockchain address that is the owner of the NFT is associated with the public key that is associated with the unique identifier; and
verifying that a private key stored in a secure area of the device is associated with the public key that is associated with the unique identifier; and
after authenticating the authentication request, enable an operation not available prior to authenticating the authentication request.